Here's the Combofix log.
ComboFix 09-12-02.05 - Dave 12/02/2009 21:28.2.1 - x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.511.162 [GMT -5:00]
Running from: c:\documents and settings\Dave\Desktop\Combo-Fix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\TEMP\{CE3E6AA4-16A5-44e2-863D-32BA5178BC62}3
c:\windows\TEMP\{CE3E6AA4-16A5-44e2-863D-32BA5178BC62}4
.
((((((((((((((((((((((((( Files Created from 2009-11-03 to 2009-12-03 )))))))))))))))))))))))))))))))
.
2009-12-02 23:37 . 2009-12-02 23:37 -------- d-----w- c:\documents and settings\DWM\Application Data\Malwarebytes
2009-12-02 03:45 . 2009-12-03 02:24 -------- d-----w- C:\Combo-Fix3178C
2009-12-02 03:37 . 2009-12-02 03:39 -------- d-----w- C:\Combo-Fix
2009-12-01 12:07 . 2009-12-01 12:07 -------- d-----w- c:\program files\mwbam
2009-12-01 03:14 . 2009-12-01 03:13 6944624 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\aaw2008_upd.exe
2009-11-29 03:07 . 2009-11-29 03:07 -------- d-----w- c:\documents and settings\Dave\Application Data\Malwarebytes
2009-11-29 02:22 . 2009-09-10 19:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-11-29 02:22 . 2009-11-29 03:06 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-11-29 02:22 . 2009-11-29 02:22 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-11-29 02:22 . 2009-09-10 19:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-11-29 02:00 . 2009-11-29 02:00 -------- d-----w- c:\documents and settings\Dave\Application Data\AVG8
2009-11-28 22:51 . 2009-11-28 22:51 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{CFBD8779-FAAB-4357-84F2-1EC8619FADA6}
2009-11-28 19:24 . 2009-11-28 19:24 17237488 ----a-w- c:\documents and settings\Dave\Application Data\Real\Update\setup\rp\RealPlayerSPGold.exe
2009-11-28 19:24 . 2009-11-28 19:24 8406648 ----a-w- c:\documents and settings\Dave\Application Data\Real\Update\setup\gtb_us\GOOGLE_TOOLBAR\GoogleToolbarInstaller.exe
2009-11-28 19:24 . 2009-11-28 19:24 10309448 ----a-w- c:\documents and settings\Dave\Application Data\Real\Update\setup\chr\ChromeInstaller.exe
2009-11-28 19:24 . 2009-11-28 19:24 64000 ----a-w- c:\documents and settings\Dave\Application Data\Real\Update\setup\RUP\inst_config\gcapi_dll.dll
2009-11-28 19:24 . 2009-11-28 19:24 52288 ----a-w- c:\documents and settings\Dave\Application Data\Real\Update\setup\RUP\inst_config\gtapi.dll
2009-11-28 19:24 . 2009-11-28 19:24 50688 ----a-w- c:\documents and settings\Dave\Application Data\Real\Update\setup\RUP\inst_config\fftbapi.dll
2009-11-28 19:24 . 2009-11-28 19:24 114688 ----a-w- c:\documents and settings\Dave\Application Data\Real\Update\setup\RUP\inst_config\compat.dll
2009-11-28 19:02 . 2009-11-29 23:06 79488 ----a-w- c:\documents and settings\Dave\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2009-11-25 18:57 . 2009-11-25 18:57 79488 ----a-w- c:\documents and settings\DWM\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2009-11-12 23:37 . 2009-11-12 23:37 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\Google
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-02 18:21 . 2008-09-13 13:35 -------- d-----w- c:\documents and settings\All Users\Application Data\Google Updater
2009-12-01 03:29 . 2007-12-15 15:09 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft
2009-12-01 03:27 . 2007-08-07 17:56 15648 ----a-w- c:\windows\system32\drivers\NSDriver.sys
2009-12-01 03:27 . 2007-08-07 17:58 15648 ----a-w- c:\windows\system32\drivers\AWRTRD.sys
2009-12-01 03:27 . 2007-07-11 18:37 12960 ----a-w- c:\windows\system32\drivers\AWRTPD.sys
2009-12-01 03:25 . 2004-08-08 12:37 -------- d-----w- c:\program files\Lavasoft
2009-12-01 03:14 . 2007-06-26 23:35 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-12-01 03:12 . 2007-11-24 00:44 -------- d-----w- c:\documents and settings\Dave\Application Data\Apple Computer
2009-12-01 02:52 . 2007-03-07 23:02 -------- d-----w- c:\program files\Common Files\AOL
2009-12-01 02:52 . 2007-03-07 23:05 -------- d-----w- c:\documents and settings\All Users\Application Data\AOL
2009-11-29 14:58 . 2004-08-03 22:44 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-11-29 02:19 . 2003-01-07 15:59 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee.com
2009-11-29 00:00 . 2004-08-03 22:44 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-11-28 19:23 . 2008-03-21 12:04 488968 ----a-w- c:\documents and settings\Dave\Application Data\Real\Update\setup\setup.exe
2009-11-27 01:58 . 2009-04-04 23:27 -------- d-----w- c:\documents and settings\DWM\Application Data\FrostWire
2009-11-26 20:57 . 2009-04-04 23:56 4506256 ----a-w- c:\documents and settings\DWM\Application Data\FrostWire\.NetworkShare\LimeWireWin4.16.6.exe
2009-11-19 02:17 . 2008-08-17 11:10 664 ----a-w- c:\windows\system32\d3d9caps.dat
2009-11-12 23:38 . 2007-04-20 02:43 -------- d-----w- c:\program files\Picasa2
2009-11-08 19:37 . 2008-09-13 13:19 166552 ---ha-w- c:\windows\system32\mlfcache.dat
2009-11-08 18:43 . 2009-04-30 22:00 -------- d-----w- c:\program files\iTunes
2009-11-06 01:30 . 2008-01-06 23:39 -------- d-----w- c:\documents and settings\Tori\Application Data\Apple Computer
2009-11-06 01:30 . 2008-01-06 23:39 -------- d-----w- c:\docume~1\Tori\Application Data\Apple Computer
2009-10-26 20:13 . 2009-10-26 20:13 0 ----a-w- c:\documents and settings\DWM\ntuser.tmp
2009-09-20 14:04 . 2009-09-20 14:04 79144 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.0.0.70\SetupAdmin.exe
2003-08-27 19:19 . 2005-02-21 12:23 36963 ------w- c:\program files\Common Files\SM1updtr.dll
.
(((((((((((((((((((((((((((((
SnapShot@2009-12-02_23.36.48 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-12-03 05:00 . 2009-12-03 05:00 16384 c:\windows\Temp\Perflib_Perfdata_a10.dat
+ 2009-12-03 03:32 . 2009-12-03 03:32 16384 c:\windows\Temp\Perflib_Perfdata_110.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}]
2008-09-09 03:08 279944 ----a-w- c:\program files\AskBarDis\bar\bin\askBar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{3041d03e-fd4b-44e0-b742-2d9b88305f98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-09-09 279944]
[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{3041D03E-FD4B-44E0-B742-2D9B88305F98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-09-09 279944]
[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"updateMgr"="c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_8 -reboot 1" [X]
"Creative Detector"="c:\program files\Creative\MediaSource\Detector\CTDetect.exe" [2004-12-02 102400]
"DellSupport"="c:\program files\DellSupport\DSAgnt.exe" [2007-03-15 460784]
"Google Update"="c:\documents and settings\Dave\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2008-09-13 133104]
"EasyLinkAdvisor"="c:\program files\Linksys EasyLink Advisor\LinksysAgent.exe" [2007-03-15 454784]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-10-19 204288]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"diagent"="c:\program files\Creative\Diagnostics\diagent.exe startup" [X]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2005-02-22 180269]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-04-04 148888]
"SM1BG"="c:\windows\SM1BG.EXE" [2003-08-27 94208]
"RoxioDragToDisc"="c:\program files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe" [2004-11-17 1691648]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"MimBoot"="c:\progra~1\MUSICM~1\MUSICM~1\mimboot.exe" [2006-01-19 11776]
"Microsoft Works Update Detection"="c:\program files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe" [2001-08-17 28738]
"Ink Monitor"="c:\program files\EPSON\Ink Monitor\InkMonitor.exe" [2001-12-07 258118]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2002-09-25 290816]
"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [2007-03-09 63712]
"Media Codec Update Service"="c:\program files\Essentials Codec Pack\update.exe" [2007-04-08 303104]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-08-13 177440]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-09-05 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-09-09 305440]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
"BCMSMMSG"="BCMSMMSG.exe" - c:\windows\BCMSMMSG.exe [2002-05-17 65536]
"ATIModeChange"="Ati2mdxx.exe" - c:\windows\SYSTEM32\Ati2mdxx.exe [2001-09-04 28672]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Picasa Media Detector"="c:\program files\Picasa2\PicasaMediaDetector.exe" [2008-08-21 443968]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
c:\documents and settings\Guest\Start Menu\Programs\Startup\
PowerReg Scheduler V3.exe [2009-2-16 225280]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2003-1-7 45056]
EPSON Status Monitor 3 Environment Check 2.lnk - c:\windows\SYSTEM32\SPOOL\DRIVERS\W32X86\3\E_SRCV02.EXE [2003-1-13 131584]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk /r \??\p:\0autocheck autochk *\0lsdelete
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\DC++\\DCPlusPlus.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"c:\\Program Files\\Roxio\\Easy Media Creator 7\\VideoWave\\VideoWave7.exe"=
"c:\\Program Files\\DC++306\\DCPlusPlus.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\WINDOWS\\SYSTEM32\\dpvsetup.exe"=
"c:\\WINDOWS\\SYSTEM32\\dxdiag.exe"=
"c:\\WINDOWS\\SYSTEM32\\dpnsvr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\WINDOWS\\SYSTEM32\\SPOOL\\DRIVERS\\W32X86\\3\\E_DPPE03.EXE"=
"c:\\WINDOWS\\BCMSMMSG.exe"=
"c:\\WINDOWS\\SYSTEM32\\imapi.exe"=
"c:\\Program Files\\DellSupport\\DSAgnt.exe"=
"c:\\Program Files\\Microsoft Office\\OFFICE11\\WINWORD.EXE"=
R2 NeatReceipts Auto Backup;NeatReceipts Auto Backup;c:\program files\NeatReceipts Professional\exec\NeatReceiptsAutoBackup.exe [9/22/2007 8:24 AM 30320]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [10/15/2007 6:31 AM 24652]
R3 MSSQL$NR2005;MSSQL$NR2005;c:\program files\Microsoft SQL Server\MSSQL$NR2005\Binn\sqlservr.exe -sNR2005 --> c:\program files\Microsoft SQL Server\MSSQL$NR2005\Binn\sqlservr.exe -sNR2005 [?]
S1 efbDisk;efbDisk; [x]
S3 FTD2XX;Nike Coach USBLink Direct Device;c:\windows\SYSTEM32\DRIVERS\FTD2XX.sys [8/2/2002 10:52 AM 23750]
S3 SQLAgent$NR2005;SQLAgent$NR2005;c:\program files\Microsoft SQL Server\MSSQL$NR2005\Binn\sqlagent.EXE -i NR2005 --> c:\program files\Microsoft SQL Server\MSSQL$NR2005\Binn\sqlagent.EXE -i NR2005 [?]
.
Contents of the 'Scheduled Tasks' folder
2009-11-27 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 17:34]
2009-12-03 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-04-20 12:32]
2009-12-03 c:\windows\Tasks\RoxioUpdator.job
- c:\program files\Common Files\Roxio Shared\Autoupdater\autoupdater.exe [2004-11-17 14:13]
.
.
------- Supplementary Scan -------
.
uDefault_Search_URL =
hxxp://search.msn.comuSearchMigratedDefaultURL =
hxxp://msxml.excite.com/info.xcite/search/web/{searchTerms}/1/-/1/-/-/-/-/-/-/-/-/-/-/-/-/-/-/-/-/-/-/-/-/-/-/-/-/-/-/-/-/-/-/-/-/-/-/-/-/-/-/-/-/-/-/-/-/-/-/-/-/-/417/topmSearch Bar = about:blank
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
IE: &AOL Toolbar Search - c:\program files\aol\aol toolbar 4.0\resources\en-US\local\search.html
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
Trusted Zone: turbotax.com
Trusted Zone: musicmatch.com\online
DPF: DirectAnimation Java Classes -
file://c:\windows\Java\classes\dajava.cabDPF: Microsoft XML Parser for Java -
file://c:\windows\Java\classes\xmldso.cabFF - ProfilePath - c:\documents and settings\Dave\Application Data\Mozilla\Firefox\Profiles\u5pukhjz.default\
FF - prefs.js: browser.startup.homepage -
hxxp://abcnews.go.com/FF - plugin: c:\documents and settings\Dave\Local Settings\Application Data\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPAdbESD.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npunagi2.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npViewpoint.dll
FF - plugin: c:\program files\Picasa2\npPicasa2.dll
FF - plugin: c:\program files\Picasa2\npPicasa3.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
FF - plugin: c:\windows\system32\npmirage.dll
FF - plugin: c:\windows\system32\npwmsdrm.dll
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-12-03 00:03
Windows 5.1.2600 Service Pack 2 NTFS
scanning hȋdden processes ...
scanning hȋdden autostart entries ...
scanning hȋdden files ...
scan completed successfully
hȋdden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(3612)
c:\program files\Windows Media Player\wmpband.dll
c:\windows\system32\WPDShServiceObj.dll
c:\program files\Roxio\Easy Media Creator 7\Drag to Disc\Shellex.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
c:\program files\Microsoft Office\OFFICE11\msohev.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Lavasoft\Ad-Aware\aawservice.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\windows\System32\Ati2evxx.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\System32\CTsvcCDA.exe
c:\program files\Common Files\EPSON\EBAPI\SAgent2.exe
c:\program files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\wanmpsvc.exe
c:\windows\System32\MsPMSPSv.exe
c:\program files\Microsoft SQL Server\MSSQL$NR2005\Binn\sqlservr.exe
c:\windows\system32\wscntfy.exe
c:\progra~1\MUSICM~1\MUSICM~1\MMDiag.exe
c:\program files\Creative\Diagnostics\diagent.exe
c:\program files\MUSICMATCH\MUSICMATCH Jukebox\mim.exe
c:\windows\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2009-12-03 00:57 - machine was rebooted
ComboFix-quarantined-files.txt 2009-12-03 05:56
ComboFix2.txt 2009-12-03 00:30
Pre-Run: 23,858,524,160 bytes free
Post-Run: 23,892,901,888 bytes free
- - End Of File - - 55E4F50CD41168563D54EF089A3F1C1E